快速搜索提示:
按厂商查询(如:microsoft)|
按产品查询(如:microsoft sql_server)
漏洞列表 352547
| CVE ID | 标题 | 严重程度 | CVSS | 发布时间 | 受影响产品 | 数据源 | 操作 |
|---|---|---|---|---|---|---|---|
| CVE-2025-13987 |
Purchase and Expense Manager <= 1.1.2 - Cross-Site Request Forgery to Arbitrary Purchase Record Deletion
|
MEDIUM | 4.3 | 2025-12-12 |
codnloc Purchase and Expense Manager
|
CVE NVD | |
| CVE-2025-13314 |
Product Filtering by Categories, Tags, Price Range for WooCommerce <= 1.1.5 - Missing Authorization to Unauthenticated Plugin Settings Modification
|
MEDIUM | 5.3 | 2025-12-12 |
markutos987 Product Filtering by Categories, Tags, Price Range for WooCommerce – Filter Plus
|
CVE NVD | |
| CVE-2025-13885 |
Zenost Shortcodes <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes
|
MEDIUM | 6.4 | 2025-12-12 |
imran3229 Zenost Shortcodes
|
CVE NVD | |
| CVE-2025-14062 |
Animated Pixel Marquee Creator <= 1.0.0 - Cross-Site Request Forgery via 'marquee' Parameter
|
MEDIUM | 4.3 | 2025-12-12 |
tekafran Animated Pixel Marquee Creator
|
CVE NVD | |
| CVE-2025-12963 |
LazyTasks – Project & Task Management with Collaboration, Kanban and Gantt Chart <= 1.2.29 - Missing Authorization to Uanuthenticated Privilege Escalation
|
CRITICAL | 9.8 | 2025-12-12 |
lazycoders LazyTasks – Project & Task Management with Collaboration, Kanban and Gantt Chart
|
CVE NVD | |
| CVE-2025-14132 |
Category Dropdown List <= 1.0 - Reflected Cross-Site Scripting via $_SERVER['PHP_SELF']
|
MEDIUM | 6.1 | 2025-12-12 |
pandikamal03 Category Dropdown List
|
CVE NVD | |
| CVE-2025-13971 |
TWW Protein Calculator <= 1.0.24 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'Header' Setting
|
MEDIUM | 4.4 | 2025-12-12 |
thewellnessway TWW Protein Calculator
|
CVE NVD | |
| CVE-2025-13906 |
WP Flot <= 0.2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes
|
MEDIUM | 6.4 | 2025-12-12 |
ysh WP Flot
|
CVE NVD | |
| CVE-2025-13988 |
评论小秘书 <= 1.3.2 - Reflected Cross-Site Scripting via $_SERVER['PHP_SELF']
|
MEDIUM | 6.1 | 2025-12-12 |
thobian 评论小秘书
|
CVE NVD | |
| CVE-2025-13966 |
Paypal Payment Shortcode <= 1.01 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'buttom_image' Shortcode Attribute
|
MEDIUM | 6.4 | 2025-12-12 |
sonlamtn200 Paypal Payment Shortcode
|
CVE NVD | |
| CVE-2025-13961 |
Data Visualizer <= 1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes
|
MEDIUM | 6.4 | 2025-12-12 |
subhransu-sekhar Data Visualizer
|
CVE NVD | |
| CVE-2025-13884 |
Hide Email Address <= 0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes
|
MEDIUM | 6.4 | 2025-12-12 |
buntegiraffe Hide Email Address
|
CVE NVD | |
| CVE-2025-14035 |
DebateMaster <= 1.0.0 - Authenticated (Administrator+) Stored Cross-Site Scripting via Color Options via 'debate' Shortcode
|
MEDIUM | 4.4 | 2025-12-12 |
jeremybmerrill DebateMaster
|
CVE NVD | |
| CVE-2025-13840 |
BUKAZU Search widget <= 3.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'shortcode' Shortcode Attribute
|
MEDIUM | 6.4 | 2025-12-12 |
bobvanoorschot BUKAZU Search widget
|
CVE NVD | |
| CVE-2025-13960 |
GPXpress <= 1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes
|
MEDIUM | 6.4 | 2025-12-12 |
davidkeen GPXpress
|
CVE NVD | |
| CVE-2025-13320 |
WP User Manager <= 2.9.12 - Authenticated (Subscriber+) Arbitrary File Deletion via 'current_user_avatar' Parameter
|
MEDIUM | 6.8 | 2025-12-12 |
wpusermanager WP User Manager – User Profile Builder & Membership
|
CVE NVD | |
| CVE-2025-13440 |
Premmerce Wishlist for WooCommerce <= 1.1.10 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Wishlist Deletion
|
MEDIUM | 5.3 | 2025-12-12 |
premmerce Premmerce Wishlist for WooCommerce
|
CVE NVD | |
| CVE-2025-14392 |
Simple Theme Changer <= 1.0. - Missing Authorization to Plugin Settings Update via AJAX Actions
|
MEDIUM | 4.3 | 2025-12-12 |
darendev Simple Theme Changer
|
CVE NVD | |
| CVE-2025-14032 |
Bold Timeline Lite <= 1.2.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'title' Parameter in 'bold_timeline_group' Shortcode
|
MEDIUM | 6.4 | 2025-12-12 |
boldthemes Bold Timeline Lite
|
CVE NVD | |
| CVE-2025-13969 |
Reviews Sorted <= 2.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'space' Shortcode Attribute
|
MEDIUM | 6.4 | 2025-12-12 |
eurisko Reviews Sorted
|
CVE NVD |